CVE-2021-35342
Last modified
CVE-2021-35342 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing invalidation (if the JWT verification cache is enabled).. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing invalidation (if the JWT verification cache is enabled).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Northern.Tech | Useradm | 1.14.0 |
| Northern.Tech | Useradm | 1.13.0 |
References
- https://mender.io/blog/cve-2021-35342-useradm-logout-vulnerabililtyThird Party Advisory
- https://northern.tech/our-productsProduct, Vendor Advisory
- https://mender.io/blog/cve-2021-35342-useradm-logout-vulnerabililtyThird Party Advisory
- https://northern.tech/our-productsProduct, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-35342?
How severe is CVE-2021-35342?
How do I fix CVE-2021-35342?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-35327A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.47…9.8
- CVE-2021-3533Rejected reason: This vulnerability does not meet the criter…
- CVE-2021-35331In Tcl 8.6.11, a format string vulnerability in nmakehlp.c m…7.8
- CVE-2021-35336Tieline IP Audio Gateway 2.6.4.8 and below is affected by In…9.8
- CVE-2021-35337Sourcecodester Phone Shop Sales Managements System 1.0 is vu…4.3
- CVE-2021-3534Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-35343Cross-Site Request Forgery (CSRF) vulnerability in the /op/o…4.3
- CVE-2021-35344tsMuxer v2.6.16 was discovered to contain a heap-based buffe…9.8
- CVE-2021-35346tsMuxer v2.6.16 was discovered to contain a heap-based buffe…9.8
- CVE-2021-3535Rapid7 Nexpose is vulnerable to a non-persistent cross-site …6.1
- CVE-2021-35358A stored cross site scripting (XSS) vulnerability in dotAdmi…4.8
- CVE-2021-3536A flaw was found in Wildfly in versions before 23.0.2.Final …4.8
Are you affected by CVE-2021-35342?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
